¶ … Cyber Attacks on Financial Institutions
Carmalia Davis
The finance industry has continued to receive more targeted and sophisticated cyber attacks from criminals. These criminals often email phishing campaigns to customers which have remained the most successful methods of targeting financial institutions. New innovations in banking, like online and mobile banking, have continued to create new vulnerabilities for cyber thieves. To minimize the efficiency of these attacks, banks have devised improved communication and educational tools for customers, and procedures for quick interventions in the event of an actual attack. However, beyond simply creating harmful software intended to hack online bank details, criminals have found ways to subvert the software and servers owned by prestigious financial institutions to make their phishing campaigns more effective; this technique is known as infrastructure hijacking (Pettersson, 2012).
In 1998, one of the foremost examples of infrastructure hijacking ever discovered is known as The Morris worm. This worm spread to several computers that were mostly in the United States and it exploited the weaknesses found in the UNIX system which allowed it to quickly replicate itself. This worm slowed computers down to the point where they could no longer be effectively used. Robert Tapan Morris created the worm and he claimed he was only attempting to discover how vast the internet was. As a result, he was the first person in history to be convicted under the United States Computer Abuse and Fraud Act. Georgian computer networks were also hacked by unidentified foreign intruders during a period in which the country experienced hostilities with Russia. Graffiti was posted on the websites of the Georgian government. Little or no services were actually disrupted, however, the Georgian government believed these attacks were coordinated by the Russian military officials. Comment by dkamari: It Comment by dkamari: Not a place==that Comment by dkamari: Serious run-on
The FBI stated that these cybercriminals have devised new means of gaining access to the login details of banking employees by using phishing and spam emails, remote access Trojans and keystroke loggers. Attacks like these were witnessed in September 2012 when Wells Fargo and Bank of America were both compromised (Fraud Alert, 2012). According to the Financial Services Information Sharing and Analysis Centre, the threat level has currently been raised from elevated to high, with reference to current reliable intelligence about potential DDoS-distributed denial-of-service attacks (United States Financial Sector has increased its Cyber Threat Level from Elevated to High, 2012). This research adopts an expository approach to give a description of cyber-attacks and compromising of data experienced in financial institutions. Comment by dkamari: said Comment by dkamari: punctuation
Cybercriminals carried out advanced offensive cyber-attacks on banks in 2014. One of the most notable cyber-attacks occurred in July, 2014, and involved a massive regional banking network that was compromised by unidentified third party, which placed the accounts of over 72, 000 customers with the risk of exposure. Investigations carried out showed that the unidentified third party could have accessed customer information, such as names, account numbers, addresses, personal identification numbers and account balances (Cordle, 2014). In a related cyber-attack a couple of weeks later involving an American bank, the biggest cybersecurity infringements occurred with more than 76 million household bank accounts and over 7 million small business bank accounts compromised. The cyber-attackers accessed the bank servers that hosted the consumer account details. As a result of the technique employed for carrying out the cyber-attack, the attack was not detected for nearly two months before the bank responded and shut down access points of more than 90 servers. The bank collaborated with crime detectives and banking regulators, with the aim of uncovering the technique used in the attack. Furthermore, the bank made sure they addressed the issues concerning the vulnerability of network systems (Glazer, 2014). Comment by dkamari: punctuation Comment by dkamari: two words Comment by dkamari: a bank is not a "they"
One unique type of cyber-attack that reduces the effectiveness of monitoring and maintaining adequate protocols for cyber security is that an attack can sometimes come from traditional methods that utilize a normal process. Thus, network system vulnerability is not quite obvious or evident to an institution in many cases. This was the situation when a well-publicized mobile payment policy was revealed and cyber criminals adopted a technique employing identity theft, instead of hacking into the payment scheme, to utilize the sign-up process of the customer to authenticate credit cards to be used on the new payment scheme (Crossman, 2015).
The cybercriminals utilized the customer's sign-in method found at the front end by accessing readily available customer details to authenticate a credit card. These criminals capitalized on the mobile payment system because most of the banks would be encouraged customers to streamline the sign-up process for credit, without asking for additional verification details to authenticate the credentials of the customer. Consequently, despite a highly secure token security system enclosed in the mobile payment policy, cybercriminals used rudimentary means to hack into customers'...
Ethical Considerations in Computer Crimes The study is based on the topic of ethical consideration in computer crimes. The rapid expansion of computer technology has resulted in an extremely sensitive issue of computer crimes. The ethical standards that are applied in other fields cannot be applied to the field of computer technology therefore the paper has discussed various aspects that are crucial for the understanding of the topic. There are a number
Spyware runs automatically without the user's knowledge and transmits vital information. Spyware can also record your keystrokes and one might end up revealing all usernames, passwords and other details to identity thieves. (Atlantic Publishing, 2008); (Schwabach, 2005) Identity thieves have also found novel ways to steal and use identities. For instance, cyber criminals recently hacked Facebook, a popular social networking site, and changed a user's page asking people to help
In one case in 2000, two-20-year-olds hacked into the Lowe's credit card mainframe from a white Pontiac Grand Prix parked outside a store, synching a single laptop to the wireless system that was meant for employees to use to locate products. The hackers, obviously to blame for the crime, played on the flaws of a computer system that should not have allowed for a security breach. While the same hackers
Jersey Shore Boardwalk e-Commerce Company Assessment for a New Jersey Shore Boardwalk Clothing Store Adopting e-Commerce In assessing the potential of a Jersey Shore-based clothing store adopting e-commerce there are several considerations that need to be taken into account. First and most significant are the relative strengths, weaknesses, opportunities and threats (SWOT) of choosing to extend the business online. A SWOT analysis is provided as part of this analysis to help guide
Managing the Relationship Between Customer and E-Banking Banking E banking or the Electronic banking is an Electronic method of money transfer or the EFT. This is a means whereby, an individual transfers money directly from different accounts by use of an Electronic system. This service allows clients to make use of computers or electronic gadgets to access the accounts information and conduct the various transactions involved. The service is beneficial for customers
Criminals don't always need to have shotguns and masks to threat and rob money; it only takes a social security number, or a pre-approved credit card application from trash to make things according to their wicked way (ID Theft, 2004). Some consumers have had credit card numbers and Social Security numbers stolen and used fraudulently or identity theft. By taking reasonable steps to protect your personal information, this can mitigate the
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now